Content Library · Advisory

Advisory 2021

Browse 447 2021 NetApp advisory records in the NetApp Black Box content library. Page 2 of 4.

Library JSON API

Showing all 120 items on this page

Advisory

Intel SA-00515 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0008/

NetApp published this final advisory covering CVE-2021-0002, CVE-2021-0003, CVE-2021-0084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00479 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0009/

NetApp published this final advisory covering CVE-2021-0004, CVE-2021-0005, CVE-2021-0006, CVE-2021-0007, CVE-2021-0008, CVE-2021-0009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35942 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0005/

NetApp published this final advisory covering CVE-2021-35942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-32761 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0004/

NetApp published this final advisory covering CVE-2021-32761; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

August 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0010/

NetApp published this interim advisory covering CVE-2021-3711, CVE-2021-3712; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

May 2021 Brocade Fabric OS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0002/

NetApp published this final advisory covering CVE-2021-27792, CVE-2021-27791, CVE-2021-27790, CVE-2021-27789, CVE-2020-15388, CVE-2020-15386, CVE-2020-15383; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2021 Apache Ant Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0007/

NetApp published this final advisory covering CVE-2021-36373, CVE-2021-36374; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-37159 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0003/

NetApp published this final advisory covering CVE-2021-37159; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34429 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0006/

NetApp published this final advisory covering CVE-2021-34429; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2021-33909 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0004/

NetApp published this final advisory covering CVE-2021-33909; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22146 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0005/

NetApp published this final advisory covering CVE-2021-22146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35039 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0004/

NetApp published this final advisory covering CVE-2021-35039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34558 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0005/

NetApp published this final advisory covering CVE-2021-34558; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-34428 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0003/

NetApp published this final advisory covering CVE-2021-34428; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SANtricity Cloud Connector; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapManager for SAP.

Open source
Advisory

CVE-2021-32078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0002/

NetApp published this final advisory covering CVE-2021-32078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31535 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0001/

NetApp published this final advisory covering CVE-2021-31535; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0009/

NetApp published this final advisory covering CVE-2021-22904, CVE-2021-22880, CVE-2021-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0004/

NetApp published this final advisory covering CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0003/

NetApp published this final advisory covering CVE-2021-22918, CVE-2021-22921; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3612 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0005/

NetApp published this final advisory covering CVE-2021-3612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3541 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0007/

NetApp published this interim advisory covering CVE-2021-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2021-35042 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0008/

NetApp published this final advisory covering CVE-2021-35042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28691 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0002/

NetApp published this final advisory covering CVE-2021-28691; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22555 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0010/

NetApp published this interim advisory covering CVE-2021-22555; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28097 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0001/

NetApp published this final advisory covering CVE-2020-28097; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2017-20005 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0006/

NetApp published this final advisory covering CVE-2017-20005; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

June 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0007/

NetApp published this final advisory covering CVE-2021-22897, CVE-2021-22901; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0004/

NetApp published this final advisory covering CVE-2021-33203, CVE-2021-33571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28169 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0009/

NetApp published this final advisory covering CVE-2021-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; Snap Creator Framework.

Open source
Advisory

CVE-2020-36387 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0006/

NetApp published this final advisory covering CVE-2020-36387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-12067 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0001/

NetApp published this final advisory covering CVE-2019-12067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2013-4536 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0002/

NetApp published this final advisory covering CVE-2013-4536; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2002-2438 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0003/

NetApp published this final advisory covering CVE-2002-2438; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

July 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0001/

NetApp published this final advisory covering CVE-2019-17543, CVE-2021-22884, CVE-2021-22901, CVE-2021-2339, CVE-2021-2340, CVE-2021-2342, CVE-2021-2352, CVE-2021-2354, CVE-2021-2356, CVE-2021-2357, CVE-2021-2367, CVE-2021-2370, CVE-2021-2372, CVE-2021-2374, CVE-2021-2383, CVE-2021-2384, CVE-2021-2385, CVE-2021-2387, CVE-2021-2389, CVE-2021-2390, CVE-2021-2399, CVE-2021-2402, CVE-2021-2410, CVE-2021-2411, CVE-2021-2412, CVE-2021-2417, CVE-2021-2418, CVE-2021-2422, CVE-2021-2424, CVE-2021-2425, CVE-2021-2426, CVE-2021-2427, CVE-2021-2429, CVE-2021-2437, CVE-2021-2440, CVE-2021-2441, CVE-2021-2444; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0002/

NetApp published this interim advisory covering CVE-2021-2388, CVE-2021-2369, CVE-2021-2432, CVE-2021-2341; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

June 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0008/

NetApp published this final advisory covering CVE-2021-3544, CVE-2021-3545, CVE-2021-3546, CVE-2020-35503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0006/

NetApp published this final advisory covering CVE-2020-4885, CVE-2020-4945, CVE-2021-20579, CVE-2021-29703, CVE-2021-29777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29702 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0005/

NetApp published this final advisory covering CVE-2021-29702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20181 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0009/

NetApp published this final advisory covering CVE-2021-20181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36385 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0004/

NetApp published this final advisory covering CVE-2020-36385; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27661 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0010/

NetApp published this final advisory covering CVE-2020-27661; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25045 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0003/

NetApp published this interim advisory covering CVE-2019-25045; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2018-25015 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0002/

NetApp published this final advisory covering CVE-2018-25015; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0007/

NetApp published this final advisory covering CVE-2021-28651, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

June 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0003/

NetApp published this final advisory covering CVE-2020-25709, CVE-2020-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Linux Kernel 5.12.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0004/

NetApp published this final advisory covering CVE-2021-3489, CVE-2021-3490, CVE-2021-3491; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3530 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0006/

NetApp published this final advisory covering CVE-2021-3530; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3516 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0005/

NetApp published this final advisory covering CVE-2021-3516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-26707 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0008/

NetApp published this final advisory covering CVE-2021-26707; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-0129 Intel BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0002/

NetApp published this final advisory covering CVE-2021-0129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-0051 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0001/

NetApp published this final advisory covering CVE-2021-0051; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

May 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0006/

NetApp published this final advisory covering CVE-2020-35504, CVE-2020-35505, CVE-2020-35506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32027 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0004/

NetApp published this final advisory covering CVE-2021-32027; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29629 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0003/

NetApp published this final advisory covering CVE-2021-29629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29628 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0002/

NetApp published this final advisory covering CVE-2021-29628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3527 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0008/

NetApp published this final advisory covering CVE-2021-3527; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30465 Opencontainers-runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0003/

NetApp published this final advisory covering CVE-2021-30465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29505 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0007/

NetApp published this final advisory covering CVE-2021-29505; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-23017 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0006/

NetApp published this final advisory covering CVE-2021-23017; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22543 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0002/

NetApp published this final advisory covering CVE-2021-22543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-20221 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0005/

NetApp published this final advisory covering CVE-2021-20221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20196 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0004/

NetApp published this final advisory covering CVE-2021-20196; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10701 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0001/

NetApp published this final advisory covering CVE-2020-10701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3559 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0006/

NetApp published this final advisory covering CVE-2021-3559; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-33587 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0007/

NetApp published this final advisory covering CVE-2021-33587; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33502 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0001/

NetApp published this final advisory covering CVE-2021-33502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33200 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0004/

NetApp published this final advisory covering CVE-2021-33200; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32640 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0005/

NetApp published this final advisory covering CVE-2021-32640; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-31440 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0003/

NetApp published this final advisory covering CVE-2021-31440; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-10688 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0008/

NetApp published this final advisory covering CVE-2020-10688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0008/

NetApp published this final advisory covering CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2020-25673; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0001/

NetApp published this final advisory covering CVE-2019-17567, CVE-2020-13938, CVE-2020-13950, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00463 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0002/

NetApp published this interim advisory covering CVE-2020-8670, CVE-2020-8700, CVE-2020-12357, CVE-2020-12358, CVE-2020-12359, CVE-2020-12360, CVE-2020-24486; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2021-33623 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0007/

NetApp published this final advisory covering CVE-2021-33623; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-27815 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0004/

NetApp published this final advisory covering CVE-2020-27815; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25724 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0003/

NetApp published this final advisory covering CVE-2020-25724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25669 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0006/

NetApp published this final advisory covering CVE-2020-25669; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25668 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0005/

NetApp published this final advisory covering CVE-2020-25668; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3483 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0002/

NetApp published this final advisory covering CVE-2021-3483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3426 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0003/

NetApp published this final advisory covering CVE-2021-3426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-33574 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0005/

NetApp published this final advisory covering CVE-2021-33574; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22138 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0001/

NetApp published this final advisory covering CVE-2021-22138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14301 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0007/

NetApp published this final advisory covering CVE-2020-14301; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-4588 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0004/

NetApp published this final advisory covering CVE-2019-4588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25044 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0006/

NetApp published this final advisory covering CVE-2019-25044; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

May 2021 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0002/

NetApp published this final advisory covering CVE-2021-3517, CVE-2021-3518, CVE-2021-3537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

May 2021 Elasticsearch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0003/

NetApp published this final advisory covering CVE-2021-22135, CVE-2021-22137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33204 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0006/

NetApp published this final advisory covering CVE-2021-33204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32606 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0001/

NetApp published this final advisory covering CVE-2021-32606; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-23134 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0007/

NetApp published this final advisory covering CVE-2021-23134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-0095 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0009/

NetApp published this final advisory covering CVE-2021-0095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2020-27830 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0004/

NetApp published this final advisory covering CVE-2020-27830; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-13529 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0005/

NetApp published this interim advisory covering CVE-2020-13529; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0004/

NetApp published this final advisory covering CVE-2019-4471, CVE-2019-4653, CVE-2019-4722, CVE-2019-4723, CVE-2019-4724, CVE-2019-4730, CVE-2020-4300, CVE-2020-4354, CVE-2020-4520, CVE-2020-4561; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2021 MySQL Client Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0001/

NetApp published this final advisory covering CVE-2020-14550, CVE-2021-2006, CVE-2021-2007, CVE-2021-2010, CVE-2021-2011; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-32399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0006/

NetApp published this final advisory covering CVE-2021-32399; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-29921 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0003/

NetApp published this final advisory covering CVE-2021-29921; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp XCP NFS; NetApp XCP SMB; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-29491 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0002/

NetApp published this final advisory covering CVE-2021-29491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29489 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0005/

NetApp published this final advisory covering CVE-2021-29489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2020-15522 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0007/

NetApp published this final advisory covering CVE-2020-15522; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2021-3501 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0008/

NetApp published this final advisory covering CVE-2021-3501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31879 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0002/

NetApp published this interim advisory covering CVE-2021-31879; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-31597 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0004/

NetApp published this final advisory covering CVE-2021-31597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0001/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0010/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29484 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0006/

NetApp published this final advisory covering CVE-2021-29484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source